Earlier quoted context omitted.
Electronic password managers never made sense to me. While you can do more to secure a single target, it is a more valuable target and one mistake costs you all your passwords. For me a physical password journal is best. While it does make you vulnerable to physical attackers, the cost invest to target someone physically is so much higher that if I have to deal with that threat level I'm already a goner. Just have to…
My approach for anything remotely sensitive, or that could be used to gain access to other accounts, is to generate a LastPass password and to memorize a handful of short "salts" that I add to each sensitive password manually + using 2FA wherever it's available. Obviously there's no 100% secure approach, but at least this makes me sleep better knowing that if LastPass were comprimized, my stored gmail, bank, paypal,…
LastPass’ Authenticator app is not secure
111–118 of 118 posts
Re: LastPass’ Authenticator app is not secure
#112I accidentally cought LastPass doctoring their terrible track record of security in wikipedia: https://news.ycombinator.com/item?id=15756044 This was just over a month ago, and published only here.
Re: LastPass’ Authenticator app is not secure
#113Earlier quoted context omitted.
> (Edit #1, 7.30pm GMT): A lot of people are saying that this flaw requires physical access. However, as I pointed out above, you don’t need physical access, a maliciously installed application can easily access the activity and capture the code.)
So you don't need physical access you just need to install a malicious application? Okay then. Why can one application even explore and access the views of another?
Re: LastPass’ Authenticator app is not secure
#114Earlier quoted context omitted.
> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.
The article that is literally not about Lastpass's password manager? Lastpass Authenticator is not their password manager. It is a Google Authenticator competitor...
Re: LastPass’ Authenticator app is not secure
#115Earlier quoted context omitted.
The article that is literally not about Lastpass's password manager? Lastpass Authenticator is not their password manager. It is a Google Authenticator competitor...
If they have a history of shitty security practices (this app), then why should we fully trust other apps they make?
Re: LastPass’ Authenticator app is not secure
#116Earlier quoted context omitted.
If they have a history of shitty security practices (this app), then why should we fully trust other apps they make?
You're going to double down on completely misreading the article and misquoting as to why their Password Manager is insecure? Come on...
https://www.theverge.com/2017/3/22/15023062/lastpass-securit...
https://www.pcworld.com/article/2936621/the-lastpass-securit...
https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...
Re: LastPass’ Authenticator app is not secure
#117I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
KeePass is anything but user friendly or convenient - it involves a lot of tinkering and not a lot of people have time, patience, or even know-how for that. It has never been and I don't see that happening in near future. In comparison LastPass is "sign up once, use everywhere". 1Password royally ignored every other platform other than the fruit company ecosystem for a really long time. See, I am not speaking as a fa…
Lastpass seems to lack a fair amount of usability polish, but it’s all relative maybe no one is better.
For example, why when adding new sites, it likes retain even super long useless query param strings that clutter the interface. Without going into detail, this is in no way technically necessary for most cases.
Also, they already have the ability to pre-associate common login sites, yet won’t do it for many popular domains. For example, there are a few stack exchange sites with different domains but that use the same credentials. Why should I have to manually set this up for a site that’s not far from the top 100 in traffic on the planet? It’s been requested, they won’t do it. Pay a damn intern to pre-associate the top 500 domains at least when needed.
There are many other practical examples.
But again, maybe the bar just isn’t that high in this category of software.
Edit: What didn’t you like about bitwardem? Haven’t had a chance to try it yet.
Re: LastPass’ Authenticator app is not secure
#118Earlier quoted context omitted.
You're going to double down on completely misreading the article and misquoting as to why their Password Manager is insecure? Come on...
Here, since you can't be bothered to do your own research before jumping to conclusions: https://www.theverge.com/2017/3/22/15023062/lastpass-securit... https://www.pcworld.com/article/2936621/the-lastpass-securit... https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...